Skip to main content

User Directory

To access Active Directory actions go to Settings > User Directory.

The Active Directory section allows you to synchronize your GravityZone Security for Email account with one or more Active Directory domains.

Note

If the email addresses you import are not part of a domain that GravityZone Security for Email is already tracking, the new mailboxes will fail to import. You can add new domains by visiting the Product Configuration page. Mailboxes will also fail to import if they already exist.

gz_cl_op_pt_walkthrough_cc_ems_activedir.png
  1. Delete button - deletes the selected synchronized domain.

  2. Add button - synchronize a new domain.

  3. Source - AzureAD tenant name.

  4. Count - number of synchronized objects from AD.

General information

  • Azure Active Directory connections require a trust relationship with Microsoft Azure/Graph API. The Azure AD will be polled for changes every 15 minutes.

  • Enabling the Only sync users with this attribute set option will limit the synchronization of user objects into the Email Security cloud account and as a result, limit the user objects synchronized with all licensed products. If you intend to use extension attributes with Azure AD, you will need to synchronize them with Azure AD using the Microsoft Azure Active Directory Connect tool. It is possible to use multiple values, separated by semi-colon ; with this attribute filter.

  • The Only sync groups with this attribute set option only limits the synchronization of groups. Users will not be excluded unless the Only sync users with this attribute set option is also used in conjunction. This group filter is purely for excluding group objects. It is possible to use multiple values, separated by semi-colon ; with this attribute filter.

  • Deleting an Active Directory connection will delete all of the objects and any reference to them will be removed.

  • If a user is a member of nested groups in Active Directory, the group membership list will be flattened when synchronized with Email Security.

  • It is not possible to specify a custom attribute to obtain email address and phone number values from when using Azure AD.

  • The account must have an email domain configured.

  • The user objects must have an email address that matches the configured email domain.

    Note

    Please note that email addresses should conform to 7-bit ASCII. Special characters introduced with the RFC 6531: SMTP Extension for Internationalized Email (SMTPUTF8) are not supported.

  • If the above conditions are met, user email addresses will appear in the Mailboxes view. If the email address is not in the Mailboxes view (or existing as an alias to an existing mailbox) then mail will be rejected.

  • Exchange distribution lists will be visible in the "Everything" section of the Active Directory view.

  • User objects must appear in the Active Directory view before they can be synchronised with the Email Security product.

  • The service will poll for changes to Active Directory objects every minute and then attempt to synchronize them with the Email Security product.

Requirements

For more information on this topic, refer to to Requirements.

Adding a domain using Azure Active Directory

Note

Before adding a domain make sure it is configured in the Product Configuration > Domains section.

  1. Click the Add domainemailsecadd.png button on the upper right of the screen and select Azure Active Directory.

    129289_1.png
  2. Enter a name under Domain. This will be used to identify this domain in the list shown in the Active Directory screen.

  3. Add your AzureAD tenant name under Tenant Name.

    Note

    For information on how to find your tenant name refer to this Microsoft kb article.

    Important

    You only need one Azure synchronization item. You can use it for all your domains.

  4. (optional) Enter a specific NetBIOS name under NetBIOS. This will only import date from a specific NetBIOS domain instead of searching automatically.

  5. (optional) Check the Only synchronize users with this attribute set box and enter the attribute name and value. This will only import the users that have this specific attribute to Email Security.

  6. (optional) Check the Only synchronize groups with this attribute set box and enter the attribute name and value. This will only import the groups that have this specific attribute to Email Security.

  7. Click the Add domain button in the upper right side of the screen.

    129289_2.png

Adding a domain using On Premise Active Directory

Note

Before adding a domain make sure it is configured in the Product Configuration > Domains section.

  1. Click the Add domainemailsecadd.png button on the upper right of the screen and select On Premise Active Directory.

    129678_5.png
  2. Fill in the domain information:

    1. Enter a name under Domain. This will be used to identify this domain in the list shown in the Active Directory screen.

    2. Under Server Hostname enter the DNS name of the domain, or the hostname or IP address of a specific domain controller.

      Note

      To use the server where the AD Connect software is installed enter localhost.

    3. Enter a valid Username and Password to connect to your domain.

    4. (optional) If you don't want to sync all the domain, uncheck the Sync Entire Domain box and enter a Enter a base DN to use as the root of the search.

    5. (optional) If you don't want to automatically detect NetBIOS names, uncheck the Automatically Detect box and enter a specific NetBIOS name to use.

    6. (optional) Check the Only synchronise users with this attribute set box and enter the attribute name and value. This will only import the users that have this specific attribute to Email Security.

      Note

      You may specify multiple values using a semi-colon separator. For example:

      attribute name = officeLocation value = London;Paris
    7. Click the Add domain button.

      129678_7.psd
  3. Click the Generate key button.

    129678_8.png
  4. Click the Add API key button.

    129678_9.png
  5. Copy the provided Client ID and Client Secret.

    129678_10.png
  6. Use the credentials to configure AD Connect.

    Note

    To configure AD Connect you need to use the AD Connect Setup Tool, which is added automatically as part of the AD Connect installation.

Adding a domain using Google Workspace

  1. Log in to Google Workspace with an administrator account.

  2. Go to the Admin section.

  3. From the menu on the left side of the screen go to Security > Access and data control > API controls and go to Domain-wide delegation.

    EMS_user_directory_google_workspace_2_129289_en.png
  4. Under the API clients section click Add new.

    EMS_user_directory_google_workspace_3_129289_en.png

    The Add a new client ID window is displayed.

  5. Type in the following information:

    • Under Client ID:

      106752148345867187443
    • Under OAuth scopes:

      https://www.googleapis.com/auth/admin.directory.user.readonly, https://www.googleapis.com/auth/admin.directory.group.readonly
  6. Click Authorise.

    EMS_user_directory_google_workspace_4_129289_en.png
  7. Go back to the Email Security console.

  8. Click the Add domainemailsecadd.png button on the upper right of the screen and select Google Workspace.

    EMS_user_directory_google_workspace_129289_en.png

    The Add Google Workspace Domain window is displayed.

  9. Type in the details for your workspace domain:

    • Under Domain name, enter your Google Workspace domain name.

    • Under Credentials, enter the username of a Google Workspace user that has permission to view users and groups

    • Select the Only synchronise users with this attribute set checkbox to specify an attribute I that must be present with the given value(s) in order for the user object to be synchronized.

      Once enabled, you need to fill in the information under Attribute name and Attribute value.You can add multiple values by using a semi-colon (;) to separate them.

  10. Click Add Domain.

    EMS_user_directory_google_workspace_5_129289_en.png

The domain is now synchronizing. This can take up to 30 minutes.

Edit domain settings

  1. Double click on the domain you want to edit.

  2. Go to the Settings tab.

  3. Make the desired modifications.

  4. Click on the Apply Changes button in the upper right side of the screen.

    129289_3.png

Synchronize Active Directory

  1. Double click on the domain you want to synchronize.

  2. Go to the Status tab.

  3. Click the Synchronize button.

    129289_4.png